mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-10 08:42:49 +03:00
pass only the request path in X-Original-URL (#24602)
nginx built X-Original-URL from the client's Host header plus the request path, so a Host containing '#' or '?' pushed the real path into the URL fragment or query. The media and go2rtc auth checks then saw an empty path and allowed restricted-role users to read other cameras' clips, recordings, exports and live streams. The header now carries only $request_uri, which is all the auth checks need.
This commit is contained in:
@@ -14,7 +14,7 @@ location /auth {
|
||||
proxy_pass_request_headers off;
|
||||
# Pass info about the request
|
||||
proxy_set_header X-Original-Method $request_method;
|
||||
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
|
||||
proxy_set_header X-Original-URL $request_uri;
|
||||
proxy_set_header X-Server-Port $server_port;
|
||||
proxy_set_header Content-Length "";
|
||||
# Pass along auth related info
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "Upgrade";
|
||||
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
|
||||
proxy_set_header X-Original-URL $request_uri;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Host $http_host;
|
||||
proxy_set_header X-Forwarded-URI $request_uri;
|
||||
|
||||
Reference in New Issue
Block a user